Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Information Security Officer

eSimplicity

Description

About Us:

eSimplicity is a modern digital services company that partners with government agencies to improve the lives and protect the well-being of all Americans, from veterans and service members to children, families, and seniors. Our engineers, designers, and strategists cut through complexity to create intuitive products and services that equip federal agencies with solutions to courageously transform today for a better tomorrow.

Purpose of Scope: The Senior Information Security Analyst will provide security compliance, risk management, vulnerability management, audit, and continuous monitoring support for a Centers for Medicare & Medicaid Services (CMS) program. This role requires extensive knowledge of FISMA, the NIST Risk Management Framework, NIST SP 800-53, and CMS Acceptable Risk Safeguards (ARS). The analyst will independently develop and maintain detailed security control implementation statements, evaluate supporting evidence, conduct Security Impact Analyses, support Authorization to Operate activities, and prepare systems for security assessments and audits. The analyst will also manage vulnerability and compliance findings throughout their lifecycle, including validation, remediation coordination, POA&M management, risk exception development, retesting, and closure. This position will work closely with CMS ISSOs, product owners, engineers, infrastructure teams, security assessors, auditors, and program leadership. The successful candidate must be able to produce accurate, audit-ready security documentation, identify compliance gaps, communicate security risks clearly, and drive assigned activities to completion with minimal supervision. Responsibilities: Serve as a senior security advisor to CMS ISSOs, product owners, engineers, infrastructure teams, and program leadership. Interpret FISMA, NIST RMF, NIST SP 800-53, CMS ARS, and agency security requirements and translate them into clear technical and operational actions. Develop, review, and maintain detailed security control implementation statements that accurately reflect the system environment, responsible parties, processes, technologies, and supporting evidence. Maintain and support ATO artifacts, including System Security Plans, Security Impact Analyses, POA&Ms, risk assessments, contingency plans, incident response plans, configuration management plans, and related documentation. Lead Security Impact Analyses for proposed system, application, infrastructure, cloud, data, and configuration changes. Support security assessments and audits by coordinating evidence collection, reviewing artifacts, responding to assessor inquiries, documenting gaps, and tracking corrective actions through closure. Review vulnerability and compliance scan results; validate findings; assess risk; and coordinate remediation with product, engineering, infrastructure, and DevSecOps teams. Develop and review vulnerability documentation, remediation plans, POA&Ms, false-positive determinations, and risk exception requests to ensure they are complete, accurate, and appropriately supported. Track vulnerability and compliance findings through assignment, remediation, mitigation, risk acceptance, retesting, and closure. Support continuous monitoring activities, access reviews, security data calls, compliance reporting, and security posture assessments. Identify control, evidence, and documentation gaps and recommend corrective actions or process improvements to reduce security risk. Develop security metrics, dashboards, status reports, and risk summaries for government stakeholders and program leadership. Maintain timely and accurate communication regarding security risks, decisions, dependencies, overdue actions, and remediation status. Mentor security team members and perform quality reviews of control statements, SIAs, audit responses, vulnerability records, risk exception requests, and other security deliverables. Requirements Minimum of 8+ years of progressive experience in information security, cybersecurity engineering, or system security roles, with demonstrated technical depth and increasing responsibility. A bachelor's degree in computer science, Information Systems, Engineering, Business, or other related scientific or technical discipline. Demonstrated experience supporting federal systems subject to FISMA and the NIST Risk Management Framework. Experience applying NIST SP 800-53 security and privacy controls and CMS ARS or comparable federal security requirements. Demonstrated experience developing, reviewing, and maintaining detailed, system-specific security control implementation statements and supporting evidence. Experience supporting ATO activities and maintaining System Security Plans, Security Impact Analyses, POA&Ms, risk assessments, contingency plans, incident response plans, configuration management plans, and related security artifacts. Experience leading or supporting security assessments and audits, including evidence collection, assessor responses, gap identification, corrective action planning, remediation tracking, and closure validation. Experience managing vulnerability and compliance findings through validation, assignment, remediation, mitigation, risk acceptance, retesting, and closure. Experience with vulnerability and compliance tools such as Tenable, Snyk, AWS Security Hub, AWS Inspector, or comparable platforms. Ability to prepare technically supported risk exception requests and vulnerability documentation that includes affected assets, vulnerability-specific risk, compensating controls, mitigation analysis, remediation plans, owners, target dates, and validation methods. Demonstrated ability to develop accurate, audit-ready documentation and communicate security requirements, risks, findings, and remediation activities to technical and non-technical stakeholders. Demonstrated ability to manage concurrent assignments, meet established deadlines, maintain accurate status reporting, and escalate risks or blockers as appropriate. Ability to obtain and maintain a Public Trust clearance and have resided in the United States for at least 3 of the last 5 years. Desired Qualifications: Direct experience supporting CMS systems, CMS security programs, or CMS ATO activities. Advanced experience applying CMS ARS 5.0 or later to security control implementation, documentation, assessment, and continuous monitoring activities. Demonstrated expertise writing and reviewing security control statements that clearly describe responsible parties, implementation methods, technologies, procedures, frequency, inheritance, and supporting evidence. Experience leading control-statement reviews or control-mapping efforts resulting from CMS ARS updates, NIST SP 800-53 revisions, cloud migrations, system modernization, or authorization boundary changes. Experience conducting Security Impact Analyses for application, infrastructure, cloud, data, integration, and configuration changes. Experience supporting Security Control Assessments, FISMA audits, Office of Inspector General reviews, internal audits, penetration tests, or independent verification and validation activities. Experience communicating directly with CMS ISSOs, security assessors, auditors, system owners, and government program leadership. Experience securing or assessing AWS cloud environments and reviewing cloud security, access management, logging, monitoring, encryption, and configuration controls. Familiarity with DevSecOps, CI/CD pipelines, source-code scanning, software composition analysis, container scanning, and security release reviews. • Experience using Jira, Confluence, and ServiceNow to manage security documentation, vulnerabilities, compliance activities, risks, and corrective actions. Experience developing security metrics, dashboards, audit-readiness reports, vulnerability reports, and executive-level risk summaries. Current certification such as CISSP, CISM, CISA, CRISC, CAP/CGRC, CCSP, or an equivalent security or audit certification. Experience mentoring security analysts and performing quality reviews of control statements, SIAs, audit responses, vulnerability records, risk exception requests, and other security deliverables. Working Environment: eSimplicity supports a remote work environment operating within the Eastern time zone so we can work with and respond to our government clients. Expected hours are 9:00 AM to 5:00 PM Eastern unless otherwise directed by your manager. Occasional travel for training and project meetings. It is estimated to be less than 5% per year. Benefits: eSimplicity offers a comprehensive benefits package, including medical, dental, and vision coverage, 401(k) retirement benefits, paid time off, paid holidays, life and disability insurance, and additional wellness and employee support programs. Eligibility may vary based on employment status and applicable plan terms. Reasonable Accommodation: eSimplicity is committed to providing reasonable accommodations to qualified individuals with disabilities during the application and hiring process. Applicants who need assistance or an accommodation should contact Human Resources. Equal Employment Opportunity: eSimplicity is an Equal Opportunity Employer, including disability and protected veteran status. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, protected veteran status, disability, or any other legally protected status.
Vacancy posted 4 days ago
Similar jobs that could be interesting for youBased on the Information Security Officer in Remote vacancy
  • The Chief Information Security Officer (CISO) is a director level role responsible for establishing and maintaining the information security program to ensure that information assets and associated technology, applications, systems, infrastructure and processes are adequately... 
    Suggested
    Full time
    Work at office
    Work from home
    Home office

    Network Health

    Neenah, WI
    2 days ago
  • $120.05k - $150.82k

     ...Connecticut, Department of Administrative Services (DAS), Bureau of Information Technology Solutions (BITS) Statewide Cybersecurity Operations team is seeking to hire an Information Security Officer (Information Technology Analyst 3) with enterprise-wide responsibility... 
    Suggested
    Full time
    Work at office
    Immediate start
    Remote work
    All shifts
    Monday to Friday
    Shift work
    Weekend work
    Day shift

    State of Connecticut, USA

    Middletown, CT
    1 day ago
  • SUMMARY The Chief Information Security Officer oversees planning and implementation of the organization’s data security programs. This includes strategy development, risk assessments and mitigation efforts and associated processes, and compliance with relevant laws and... 
    Suggested
    Remote work

    Safariland

    Jacksonville, FL
    3 days ago
  • What success looks like in this role: Position SummaryThe Unisys Information Security Officer (ISO) provides dedicated cybersecurity leadership in support of the client. This role is responsible for helping the client implement, manage, and govern information security... 
    Suggested
    Full time
    Contract work
    Remote work
    2 days per week
    1 day per week

    Unisys

    Richmond, VA
    16 hours ago
  • RotterdamTechnical - R&D /Full-time /HybridAbout Us: Mendix, part of Siemens Digital Industries Software, is looking for a proactive Information Security Officer to help protect our information assets, strengthen compliance with evolving regulations, and build a security-first... 
    Suggested
    Full time
    Remote work

    Mendix

    Rotterdam, NY
    4 days ago
  •  ...place you can engage in meaningful work and grow your career. Let’s see what we can achieve. Together.SummaryThe Chief Information Security Officer (CISO), working in collaboration with and in support of the firm’s strategic initiatives, is a senior executive responsible... 
    Full time
    Work at office
    Remote work
    Relocation
    Visa sponsorship
    Relocation package

    DLA Piper

    Reston, VA
    16 hours ago
  •  ...the nation’s leading public institutions, seeks an experienced, dynamic, and mission-driven leader to be the next Chief Information Security Officer (CISO). Reporting to the Vice President and Chief Information Officer (CIO), the CISO will provide strategic leadership... 
    Contract work
    Remote work

    University of Virginia

    Charlottesville, VA
    1 day ago
  •  ...Chief Information Security Officer (CISO) Department: Information Technology & Security Reporting to: Chief Technology Officer Location: New York, NY (One State Street Plaza) Role Type: Hybrid, Full-Time --------------------------------------------------... 
    Full time
    Work at office
    Remote work
    Worldwide
    Flexible hours

    IPC Systems

    New York, NY
    1 day ago
  • $300k - $380k

    Obsidian Security is the leading SaaS security platform, trusted by global enterprises like...  ...role reports to the Chief Legal and Trust Officer.ResponsibilitiesSecurity Strategy &...  ...support thought leadership positioning and inform messaging around trust and security.Customer... 
    Work from home

    Obsidian Security

    Palo Alto, CA
    2 days ago
  •  ...Seeking a hands-on Chief Information Security Officer, the full-time remote role will build and lead the internal security program, ensuring the protection of people, systems, infrastructure, and company data while collaborating with cross-functional teams to implement... 
    Full time
    Remote work

    Virtual Vocations Inc

    United States
    3 days ago
  •  ...To support various cybersecurity initiatives, the full-time remote Information Security Officer will manage compliance, risk, and controls while developing security policies and procedures, advising on security controls, and overseeing disaster recovery plans. Key responsibilities... 
    Full time
    Work experience placement
    Remote work

    Virtual Vocations Inc

    United States
    5 days ago
  •  ...Chief Information Security Officer (CISO)Location: Houston, TX (On-Site)Type: Full-TimeAbout Us:Our client is a leading provider specializing in laboratory testing services, dedicated to delivering accurate, timely, and high-quality diagnostic results. Their commitment... 
    Remote work

    Saviance

    Houston, TX
    2 days ago
  •  ...Chief Information Security OfficerThe Chief Information Security Officer provides enterprise leadership for the company's cybersecurity, risk management, compliance, IT infrastructure, end-user technology operations, and enterprise data governance. This executive role... 
    Hourly pay
    Temporary work
    Work at office
    Work from home
    Home office
    2 days per week
    3 days per week

    RunBuggy

    Tempe, AZ
    2 days ago
  •  ...hybrid work schedule of at least 2 days in office per week. This role is for Vice President...  ...” which performs business functions. Information Risk Governance (“IRG”) provides oversight to information and cyber security risk by maintaining and improving branch wide... 
    Work at office
    Work from home
    Flexible hours
    2 days per week

    Sumitomo Mitsui Trust Bank Limited New York Branch

    New York, NY
    4 days ago
  •  ...Role Description This full-time remote Chief Information Security Officer (CISO) role is responsible for leading Nova Infra Invest’s information security strategy and operations. The CISO oversees the design, implementation, and continuous improvement of security policies... 
    Full time
    Remote work

    Nova Infra Invest

    New York, NY
    2 days ago
  •  ...Job TitleThe position is located in the Office of the Chief Information Officer (OCIO) at the Department of the Interior (Department) and reports...  ...out the following specific responsibilities:Set enterprise security strategy. Define company-wide security policy, standards,... 
    Work at office
    Remote work

    Department of the Interior

    Denver, CO
    5 days ago
  •  ...Summary The Chief Information Security Officer oversees planning and implementation of the organization’s data security programs. This includes strategy development, risk assessments and mitigation efforts and associated processes, and compliance with relevant laws and... 
    Remote work

    Safariland

    Jacksonville, FL
    5 days ago
  • $275k - $305k

     ...resolution services business, and over $11Bn in personal and home loans originations via our banking‑as‑a‑service partner. Chief Information Security Officer (CISO) is responsible for establishing and executing the enterprise cybersecurity strategy for a high‑growth, private... 
    Contract work
    Remote work
    Work from home
    Shift work

    ACHIEVE

    Phoenix, AZ
    3 days ago
  •  ...NVISO is a pure‑play European cyber‑security consulting firm: our team of security professionals...  ...fast, with clients in 16 countries, and offices in Brussels, Frankfurt, Munich, Vienna,...  ...We are looking for an experienced Chief Information Security Officer to join our growing... 
    Work experience placement
    Work at office
    Work from home
    Home office
    Flexible hours

    NVISO

    Mobile, AL
    3 days ago
  •  ...Chief Information Security Officer (CISO) Organization: Nymbus Location: Fully remote; occasional travel may be required for client meetings and team gatherings. Description: About the job ABOUT NYMBUS: Nymbus is a modern fintech company delivering... 
    Contract work
    Remote work
    Night shift

    The Security Executive Council

    Jacksonville, FL
    1 day ago
  •  ...Information Security Strategy LeaderProvide leadership for the development and implementation of a comprehensive Information Security strategy for the University of Akron. Manage a team of information security staff, and work with members of Information Technology and... 
    Contract work

    UAkron

    Akron, OH
    1 day ago
  •  ...Lineation is building the security and governance layer for the agentic enterprise. As AI agents increasingly act across applications...  .... The Opportunity We are seeking a forward-thinking Chief Information Security Officer (CISO) to help define what security leadership looks like... 
    Remote work
    Shift work

    Lineation AI

    Carlsbad, CA
    5 days ago
  •  ...Always hire up, never down. We partner with organizations of all sizes to explore, design, and implement AI strategies that are secure, scalable, and human-centered. We believe AI should amplify human potential, not replace it, and we build with that conviction in every... 
    Full time
    For contractors
    Remote work
    Day shift

    Human Agency

    New York, NY
    4 days ago
  •  ...Chief Information Security Officer (CISO) / Head of Information Security Overview We are seeking an experienced Information Security Leader to define and execute a comprehensive enterprise security strategy. This role is responsible for safeguarding systems, data, and... 
    Work at office
    Remote work
    3 days per week

    Ryde Technologies

    Phoenix, AZ
    5 days ago
  •  ...Job Description The Chief Information Security Officer (CISO) is responsible for developing, implementing, and leading the enterprise cybersecurity, information risk management, and compliance strategy across a multi-site manufacturing organization. CISO partners with... 
    Contract work
    Remote work

    Mission Critical Group

    Tempe, AZ
    1 day ago
  • The Chief Information Security Officer will be responsible for defining, leading, and advancing Spring Health’s enterprise-wide information security, technology risk, compliance, and IT strategy This leader will ensure the protection of company assets, customer data, member... 
    Remote work
    Flexible hours

    SpringHealth Behavioral Health & Integrated Care

    San Francisco, CA
    5 days ago
  • $68.9k - $131.1k

     ...Requirements:Active and transferable U.S. government issued security clearance is required prior to start date.​ U.S....  ...team:Role Overview:RTX BBN has an immediate opening for an Information Systems Security Officer (ISSO). The role of the ISSO is to bridge the gap between... 
    Temporary work
    Work experience placement
    Work at office
    Immediate start
    Remote work
    Flexible hours

    Raytheon

    Middletown, RI
    4 days ago
  • $100k - $140k

     ...Intelligence Communities in support of national security.Rincon Research Corporation seeks a self-...  ...security position at its Chantilly, Virginia office. The security position will primarily be focused on providing Information System Security Officer (ISSO) support for local... 
    Full time
    Temporary work
    For contractors
    Work at office
    Local area
    Remote work
    Flexible hours

    Rincon Research

    Chantilly, Loudoun County, VA
    3 days ago
  • $61.9k - $141k

    Information System Security OfficerThe Opportunity: Are you looking for an opportunity to share your experience in system security engineering to...  ...Experience with working as an Information System Security Officer (ISSO), or a role in Information Technology or IT Service... 
    Full time
    Contract work
    Part time
    Interim role
    Work at office
    Local area
    Remote work

    Booz Allen Hamilton

    Warner Robins, GA
    16 hours ago
  • $118k - $130k

    DescriptionInformation Security Principal EngineerTTEC is seeking an Information Security Principal Engineer to join our Information Technology team.Our global IT organization of 500 supports the entire enterprise that encompasses over 40,000 users across our businesses... 
    Work experience placement
    Remote work

    TeleTech Holdings

    Austin, TX
    4 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Information Security Officer. Be the first to apply!